Privacy Policy
How Mtrix handles the personal data it controls — about our customers and people who visit mtrix.io. The behavioural data we process on a customer's behalf through the platform is governed by our Data Processing Addendum, not this policy.
1. Introduction & scope
This policy covers the personal data Mtrix controls — about the people and businesses who buy from us, talk to us, or visit mtrix.io. The behavioural data we collect on a customer's behalf through the platform is governed by our DPA, not this policy.
Mtrix Inc. ("Mtrix", "we", "us", "our") builds an all-in-one analytics and experimentation platform for ecommerce and direct-to-consumer brands. We have operated since 2022, and our registered office is at Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia.
This Privacy Policy explains how we handle Personal Data for which Mtrix is the controller — meaning the data where we decide why and how it is processed. In practice that is two narrow categories: Customer Account Data (the details of our customers and their teams) and Service Operations Data (the limited telemetry we use to secure, operate, debug, bill and improve the platform).
It applies to:
- customers and prospective customers;
- the Authorized Users who log in to a Mtrix account;
- people who email us, request a demo, apply for a job, or subscribe to our updates; and
- visitors to mtrix.io and our product app.
It does not apply to the data we process on a customer's behalf. When a business installs the Mtrix SDK on its own store, we ingest its visitors' ("End Users'") behavioural data — analytics and clickstream events, session recordings, experiment exposures, and performance and error telemetry — strictly on that business's instructions. For all of that Customer End-User Data, the customer is the controller and Mtrix is a processor (or sub-processor). It is governed by our Data Processing Addendum and by the customer's own privacy notice, not by this policy. If you are an end user of a store that uses Mtrix, see "Our two roles" below for how to exercise your rights.
This policy sits alongside our companion documents: the Data Processing Addendum (how we process customer data), the Cookie Policy (the cookies we set on our own site), the Security page (how we protect data), and our Terms of Service (the agreement that governs use of Mtrix). Capitalized terms not defined here have the meaning given in our Terms of Service or DPA.
2. Our two roles
For our own account and operations data, Mtrix is the controller and this policy applies. For the end-user data our customers capture through Mtrix, we are a processor acting only on their instructions — that is governed by our DPA, and rights requests go to the customer.
Mtrix wears two hats, and which one applies decides whose rules govern your data.
As a controller (this policy). We decide the purposes and means of processing for Customer Account Data and Service Operations Data — the information about our customers, their teams, and how our own platform is used and performs.
As a processor or sub-processor (our DPA). We process Customer End-User Data only on the customer's documented instructions. We do not decide what is collected, we do not use it for our own purposes, and we never sell it or share it for cross-context behavioural advertising.
Why this matters for your rights. If you interact with one of our customers' websites, the business running that site is the controller of your data. To access, correct, or delete it, or to object or withdraw consent, contact that business directly. We provide commercially-reasonable assistance to the customer so they can respond — for example, tooling to find, export, or delete a single end user's data across every Mtrix module — but we cannot lawfully action an end-user request without the customer's instruction, because we do not control that data. See our DPA for the full processor terms.
3. Information we collect
Mostly the basics needed to run your account and our business — who you are, how to reach you, how you pay, what you ask us, and how you use mtrix.io. We collect this from you and from the systems you use to interact with us.
As a controller, we collect the following categories of Personal Data. We collect only what we need for the purposes described in this policy.
Account and contact data
Your name, work email, employer or organisation, role or job title, an optional phone number, and the content of forms you submit (demo requests, sales enquiries, newsletter sign-ups, job applications).
Authentication data
Login credentials (we store passwords only as salted hashes), single sign-on identifiers, multi-factor enrolment, and session tokens. If you sign in with a third-party identity provider, we receive the basic profile that provider shares.
Billing and transaction data
Your plan, billing contact, billing address, VAT or tax identifier, invoices, and a record of payments. Card and bank details are collected and processed by our payment sub-processor — Mtrix stores a payment token and the last four digits, not full card numbers.
Support and communications
The emails, chats, and tickets you send us and our replies, call notes, and any diagnostic information you choose to share when we help you.
Marketing data
Your preferences and consents, the events and webinars you register for, and how you engage with our emails and ads (such as opens and clicks) where the law allows.
Website usage, device, and log data
When you visit mtrix.io or use the product app, we collect your IP address, the approximate city, region, and country derived from it, browser and device type, operating system, referring and exit pages, pages viewed, actions taken, and timestamps, together with the cookies and similar technologies described in our Cookie Policy.
Product-usage telemetry (Service Operations Data)
Account-level signals about how the platform is used and performs — feature usage, API call volumes, and security, fraud, and error signals — that we use to keep the service reliable and secure.
Sources. We collect this data directly from you; automatically as you use our site and product; from your colleagues who invite you to an account; and from a limited set of providers (our payment, email-delivery, support, and analytics sub-processors, and publicly-available business sources used for prospecting where permitted).
We dogfood our own product. We run Mtrix on mtrix.io, so some of the data above is collected using Mtrix itself. Where we record sessions or track events on our own site, that is Service Operations Data we control as described here, and it is subject to the same default masking and PII-scrubbing described in "Session recording and sensitive data" below.
What this section does not include. It does not include Customer End-User Data — the behavioural data we ingest on a customer's behalf through the SDK on their store. That is processor data governed by the DPA; the categories, retention, and rights for it are described there.
4. How & why we use your information
We use account and operations data to provide the platform, run our business, keep things secure, comply with the law, and — only where you have agreed — to market to you. Each use rests on a specific legal basis under the GDPR.
Under the EU GDPR (and the equivalent UK and Swiss law), every use of Personal Data needs a lawful basis. Here is what we do and the basis we rely on.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide and administer the Services | Create and secure your account, authenticate logins, deliver features, provide support | Performance of a contract (Art. 6(1)(b)); legitimate interests where you are a user on someone else's account |
| Billing and payments | Invoice you, process payments, prevent payment fraud | Performance of a contract; legal obligation for tax and accounting (Art. 6(1)(c)) |
| Secure and operate the platform | Monitor for abuse and intrusions, debug, maintain backups, plan capacity | Legitimate interests (Art. 6(1)(f)) in running a safe, reliable service |
| Improve and develop the Services | Analyse aggregate product usage, prioritise features, fix errors | Legitimate interests in improving our product |
| Communicate with you | Service and security notices, billing and policy updates, responses to your requests | Performance of a contract; legitimate interests; legal obligation |
| Marketing | Newsletters, product news, event invitations | Consent (Art. 6(1)(a)) where required, or legitimate interests for business messages to existing customers — always with an easy opt-out |
| Comply with law and protect rights | Respond to lawful requests, enforce our Terms, establish or defend legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance them against your rights and only proceed where ours are not overridden; you can object at any time (see "Your privacy rights").
Where we rely on consent — for example, non-essential cookies or certain marketing — you can withdraw it at any time, without affecting processing already carried out.
We will not use your Personal Data for a new, incompatible purpose without telling you and, where required, obtaining your consent.
5. Cookies & tracking on mtrix.io
Our website and app use a small set of cookies and similar technologies. Essential ones keep the site working; the rest only run with your consent. We honour Global Privacy Control.
mtrix.io and our product app use cookies, local storage, pixels, and similar technologies. We group them into four categories: strictly necessary (sign-in, security, load balancing), functional (remembering your preferences), performance and analytical (understanding how the site is used), and marketing (measuring campaigns).
Strictly necessary cookies are always on, because the site cannot work without them. Everything else stays off until you agree through our consent banner, and you can change your choice at any time.
We respect the Global Privacy Control (GPC) signal: where your browser sends GPC, we treat it as a valid opt-out of non-essential analytics and any "sale" or "share" of personal data, as applicable. Because there is no consistent, broadly-adopted Do Not Track standard, we do not rely on DNT headers — we act on GPC instead.
For the full list of cookies, their purposes and lifetimes (cookies last up to roughly twelve months), and how to manage them, see our Cookie Policy.
This only concerns cookies Mtrix sets on its own properties. Cookies and instrumentation that the Mtrix SDK drops on a customer's website are Customer End-User Data — the customer controls them and is responsible for consent there. See the Cookie Policy and the DPA.
6. Session recording & sensitive data
Session replay is privacy-first by default. We mask the contents of text and form fields, never capture passwords or payment fields, and suppress sensitive inputs on the device before anything is sent to us.
Mtrix includes session recording (replay), heatmaps, and error and performance monitoring. These run mostly in our customers' deployments, but we apply the same protections on our own site, and we build the product so that sensitive data is minimised by design.
-
By default, Mtrix masks the contents of text inputs, form fields, and payment
fields. Passwords and fields carrying standard sensitive attributes — for
example an input with
type=passwordor anautocomplete=cc-*value — are never captured at all. - Sensitive inputs are suppressed on the end user's device, in the browser, before any data leaves it. That means Mtrix never receives the masked content — it is not transmitted and then hidden; it is never sent.
-
Customers can tighten or loosen what is captured using CSS-selector blocklists and
allowlists and the
data-mtrix-maskanddata-mtrix-unmaskattributes. Configuring masking, and obtaining any consent the law requires for recording, is the customer's responsibility as the controller. - Error and performance payloads — stack traces, request and response bodies, and URLs — are scrubbed for personal data by default before they are stored.
- Any recordings or inputs a customer deliberately chooses to capture as sensitive are held in isolated, access-restricted storage.
- Mtrix never sells personal data and never shares it for cross-context behavioural advertising — not the data we control, and not the data we process for customers.
Because the same masking protects mtrix.io, the recordings and telemetry we collect about our own site are minimised in exactly this way. The detailed processor-side commitments for customer deployments live in our DPA.
7. How we share information
We do not sell your data and we do not share it for advertising. We share it only with vetted providers who help us run Mtrix, in a corporate transaction, or where the law requires it.
We never sell Personal Data, and we never share it for cross-context behavioural advertising. We share Personal Data only in the limited situations below.
Sub-processors and service providers. We run the Mtrix Service on Amazon Web Services (AWS), which hosts our infrastructure, databases and storage in the EU and processes Personal Data on our behalf under a written contract that restricts it to our instructions. We operate the other parts of the Service — including email delivery, error and performance monitoring, and customer support — ourselves on that infrastructure rather than through third parties. AWS is currently our only sub-processor; the current list, with purposes and locations, is in Annex III of our DPA, which also describes how we notify customers of changes.
Affiliates. We may share data within the Mtrix corporate group where needed to provide and support the Services, under the same protections described here.
Business transfers. If Mtrix is involved in a merger, acquisition, financing, reorganisation, or sale of assets, Personal Data may be transferred as part of that transaction. We will require the recipient to honour this policy, and we will notify you of any change of controller and of choices you may have.
Legal and safety disclosures. We may disclose information where we believe in good faith it is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms and policies; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Mtrix, our users, or the public. Where permitted, we will challenge overbroad requests and tell affected customers.
Aggregated or de-identified data. We may share aggregated or de-identified information that cannot reasonably be used to identify you — see "Automated decisions, profiling and de-identified data".
8. International data transfers
We are an EU company and host data in the EU/EEA by default. When a provider sits outside the EEA, we use approved legal safeguards — adequacy decisions or the EU Standard Contractual Clauses, plus the UK and Swiss equivalents.
Mtrix is established in Estonia, in the European Union, and we host and primarily process Personal Data in the European Union / EEA. EU data residency is our default.
Sometimes a sub-processor is located outside the EEA. When that happens, Mtrix acts as the data exporter and relies, in order, on:
- an EU adequacy decision where one exists for the destination country; or otherwise
- the EU Standard Contractual Clauses (Commission Decision 2021/914), incorporating Module Two (controller-to-processor) and Module Three (processor-to-processor) as relevant; and where the importer is a US entity certified under the EU-US Data Privacy Framework, we may also rely on that certification.
For UK end-user data leaving the UK, we use the UK International Data Transfer Addendum (IDTA) to the SCCs. For data subject to Swiss law, we use the Swiss adaptation of the SCCs recognised by the FDPIC.
Where we use the SCCs, their governing law and forum is Estonia, aligned with our Terms. We also carry out transfer risk assessments and apply supplementary measures — such as encryption in transit and at rest and strict access controls — where appropriate.
You can ask us for more detail about the safeguards that apply to a given transfer using the contact details below. The processor-side transfer terms for Customer End-User Data are set out in our DPA.
9. Data retention & deletion
We keep account and operations data for as long as you have an account, then delete or de-identify it — except where law (such as Estonian accounting and tax rules) requires us to keep certain records for up to seven years. Customer end-user data has its own, customer-configurable windows.
We keep Personal Data only as long as we need it for the purposes in this policy, then delete or irreversibly de-identify it.
Data we control:
- Customer Account Data — for the life of your account, and for a reasonable wind-down period after it closes. We retain accounting and transaction records for as long as required by Estonian accounting and tax law — for the life of the account plus up to seven years.
- Service Operations Data — security and operational logs are kept for a limited period proportionate to the purpose (typically months, not years), after which they are deleted or aggregated.
- Marketing data — until you unsubscribe or withdraw consent, plus a short suppression record so we can keep honouring your opt-out.
- Support communications — for the life of the account plus a reasonable period to handle follow-up questions and disputes.
Customer end-user data (processor data we hold for customers). Retention is configurable by each customer in-product. The defaults are:
| Data type | Default retention |
|---|---|
| Session recordings | 30 days by default (customer-configurable, 7–180 days) |
| Raw analytics / event data | 24 months by default |
| Heatmap data | Derived from events; the same window as events |
| Performance and error telemetry (including stack traces) | 12 months by default |
| A/B experiment-assignment data | The duration of the experiment plus 12 months |
These are defaults each customer can change in-product, within the ranges shown; they are not hard limits. When a window passes, data is automatically deleted or de-identified. Full details, including post-termination return and deletion, are in the DPA.
10. How we protect your information
We protect data with encryption, strict access controls, and other industry-standard measures, and we host in the EU/EEA. No system is ever completely secure, but we work hard to keep yours safe.
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, least-privilege access controls and MFA for staff, multi-tenant isolation, network and application security controls, logging and monitoring, secure development practices, and regular backups.
For a full description of our security program and the measures referenced by our DPA, see our Security page.
No method of transmission or storage is ever completely secure, and we cannot guarantee absolute security. Please help us by keeping your credentials confidential, enabling MFA, and telling us promptly about anything suspicious at security@mtrix.io.
If a personal-data breach affecting data we control occurs, we will act without undue delay. Our breach-notification commitments for customer data — including notifying affected customers without undue delay and within 72 hours of confirming a personal-data breach — are set out in the DPA.
11. Automated decisions, profiling & de-identified data
Mtrix does not make decisions about you that have legal or similarly significant effects without a human in the loop. We may create aggregated or de-identified data, which we do not try to re-link to you.
We do not use your Personal Data to make solely-automated decisions that produce legal effects concerning you, or that similarly significantly affect you, within the meaning of Article 22 of the GDPR.
Our product runs experiments (A/B tests, multi-armed bandits, audience targeting) on our customers' behalf. Those are optimisation tools, designed to be human-in-the-loop: a person configures and reviews them, and they are not intended to produce legally or similarly significant effects on individuals. Customers are responsible for using experimentation honestly and lawfully under our Terms.
We may aggregate or de-identify Personal Data so that it no longer reasonably identifies you. We reserve the right to create and use such Aggregated / De-identified Data — for example, to produce benchmarks, improve our models, and report on platform performance. When we do, we commit not to attempt to re-identify you, we maintain the data in de-identified form, and we never sell it. The corresponding usage-data and de-identified-data terms are set out in our Terms.
12. Your privacy rights
Depending on where you live, you can access, correct, delete, port, restrict, or object to our use of your data, and withdraw consent. Email privacy@mtrix.io and we will help — free, and usually within a month.
Subject to your local law, you have the right to:
- access the Personal Data we hold about you;
- correct inaccurate or incomplete data;
- delete it (the right to erasure);
- restrict or object to certain processing, including direct marketing;
- data portability;
- withdraw consent where we rely on it; and
- not be subject to solely-automated decisions with legal or similarly significant effects.
You also have the right to lodge a complaint with a supervisory authority (see "Region-specific disclosures").
How to exercise your rights. Email privacy@mtrix.io or use the contact details below. We will verify your identity, respond free of charge in most cases, and aim to reply within one month (extendable by two further months for complex requests, with notice). We may decline or charge for manifestly unfounded or excessive requests, as the law allows. Exercising a right will never cause us to discriminate against you or degrade the service you receive.
Requests about end-user data. If your request concerns data held by a business that uses Mtrix on its own website — for example a store you bought from — that business is the controller. Please contact them directly. If you reach us by mistake, we will, where we can, forward your request to the relevant customer and assist them in responding, but we cannot action it ourselves. See "Our two roles" and the DPA.
13. Region-specific disclosures
Some regions add specific rights and contacts. Here is what applies in the EU/EEA, the UK, Switzerland, and the United States.
EU/EEA, UK and Switzerland
Mtrix's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). If you are in the EU/EEA and believe we have mishandled your data, you can complain to it at https://www.aki.ee/en or to your local data protection authority. UK residents may complain to the Information Commissioner's Office (ICO). Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC). The rights above are your GDPR, UK GDPR, and Swiss FADP rights; our legal bases are in section 4 and our transfer safeguards in section 8.
United States (California and other states)
If you are a US resident, you may have rights under state privacy laws such as the California Consumer Privacy Act as amended by the CPRA, and similar laws in Virginia, Colorado, Connecticut, Utah, and other states. These typically include the right to know and access, to delete, to correct, to opt out of any "sale" or "sharing" of personal data and certain targeted advertising and profiling, and to non-discrimination.
Mtrix does not sell your Personal Data and does not share it for cross-context behavioural advertising, as those terms are defined under California law. We do not use or disclose sensitive personal information for purposes that would require an opt-out beyond what we already provide.
Where you act as a business that uses Mtrix to process your own consumers' data, Mtrix is your service provider / processor and handles that data only as permitted by the CCPA/CPRA and our DPA — we will not retain, use, or disclose it except to provide the Services, and we will not combine it with data from other sources except as the law permits.
You can exercise your state-law rights by emailing privacy@mtrix.io, and you may use an authorised agent where the law allows. We honour the Global Privacy Control as a valid opt-out signal for browsers that send it.
14. Children's data
Mtrix is not for children, and we do not knowingly collect their data.
Mtrix is a business-to-business product. Our website and platform are not directed to children, and we do not knowingly collect Personal Data from children under 16 in the EU/EEA, or under 13 in the United States. If you believe a child has provided us Personal Data that we control, contact us and we will delete it.
Because our SDK runs on our customers' websites and cannot reliably tell whether a visitor is a minor, customers must not use Mtrix to knowingly collect data from children where prohibited, and must configure masking and exclusions and obtain any required consent. Responsibility for the lawfulness of collecting children's data through a customer's site sits with that customer, as set out in our DPA.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top. For material changes that affect data we control about you, we will give reasonable advance notice — at least 30 days where the change is significant — by email or an in-product or on-site notice before it takes effect, and, where required, we will seek your consent.
If you keep using Mtrix after a change takes effect, you accept the updated policy. We keep prior versions and can provide an earlier version on request.
16. How to contact us
Mtrix Inc. is the controller of the Personal Data described in this policy. You can reach us at:
- Privacy, data protection and DPO matters (including data-subject requests)
- privacy@mtrix.io
- Registered office
- Mtrix Inc., Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia
We have appointed a privacy lead who handles data-protection and DPO-related matters and can be reached at the same address.
If you are an end user of a website that uses Mtrix and want to exercise rights over your data, please contact the business that runs that website — they are the controller. See "Our two roles" above.